CatKaiser Posted February 16, 2013 Share Posted February 16, 2013 Good day, I happen to find myself some virus like script named trojan-dropper.win32.autoit From what I've found on the net, it's a script written on autoit. The problem is that my computer is not infected by it, however every couple of hours my antivirus finds some infected files on my external hdd like calculator.exe and others which he deletes. So my question is how can I trace the origin of the script that creates these files, and how to trace the origin of the place this script starts from. Thanks is advance. Link to comment Share on other sites More sharing options...
Moderators Melba23 Posted February 16, 2013 Moderators Share Posted February 16, 2013 CatKaiser,Welcome to the AutoIt forum. I am sorry that your first contact with AutoIt has been in such unpleasant circumstances. However, AutoIt itself is not a virus - however some AV companies flag compiled AutoIt executables as such. This is because every compiled AutoIt executable uses the same interpreter stub to run - so when someone does write malware in AutoIt they also implicate every other AutoIt script. Alas there is nothing that we can do about it - we have repeatedly informed the AV companies of this problem but they still flag AutoIt on occasion. As AutoIt is widely used I am afraid there is no way that you can trace the origins of this script unless you are very lucky. All I can do is suggest that you use reputable AV software to prevent future infections. Bear in mind that all languages can produce malware - so please do not blame AutoIt itself. As you can see from the Forum rules (there is also a link at bottom right of each page) we do not support the coding of malware with AutoIt on this forum - but unfortunately we cannot prevent others from misusing it. However, I believe that that the good uses of AutoIt far outweigh the bad - even if that is small comfort to you. I hope that is a good enough explanation. M23 Rickname 1 Any of my own code posted anywhere on the forum is available for use by others without any restriction of any kind Open spoiler to see my UDFs: Spoiler ArrayMultiColSort ---- Sort arrays on multiple columnsChooseFileFolder ---- Single and multiple selections from specified path treeview listingDate_Time_Convert -- Easily convert date/time formats, including the language usedExtMsgBox --------- A highly customisable replacement for MsgBoxGUIExtender -------- Extend and retract multiple sections within a GUIGUIFrame ---------- Subdivide GUIs into many adjustable framesGUIListViewEx ------- Insert, delete, move, drag, sort, edit and colour ListView itemsGUITreeViewEx ------ Check/clear parent and child checkboxes in a TreeViewMarquee ----------- Scrolling tickertape GUIsNoFocusLines ------- Remove the dotted focus lines from buttons, sliders, radios and checkboxesNotify ------------- Small notifications on the edge of the displayScrollbars ----------Automatically sized scrollbars with a single commandStringSize ---------- Automatically size controls to fit textToast -------------- Small GUIs which pop out of the notification area Link to comment Share on other sites More sharing options...
CatKaiser Posted February 16, 2013 Author Share Posted February 16, 2013 Thank you for the reply. I lost my trust in the AV program, as soon as after deleting it with kaspersky it showed up again few hours later. I wanted to trace it down on my pc manually and remove anything related to it. Personally I have nothign against autoit, however the virus title got autoit in it, so i thought maybe there is a way to remove it from the inside. Link to comment Share on other sites More sharing options...
Moderators Melba23 Posted February 16, 2013 Moderators Share Posted February 16, 2013 CatKaiser, That name is just a generic one chosen by the AV company - it is not related to any particular script. M23 Any of my own code posted anywhere on the forum is available for use by others without any restriction of any kind Open spoiler to see my UDFs: Spoiler ArrayMultiColSort ---- Sort arrays on multiple columnsChooseFileFolder ---- Single and multiple selections from specified path treeview listingDate_Time_Convert -- Easily convert date/time formats, including the language usedExtMsgBox --------- A highly customisable replacement for MsgBoxGUIExtender -------- Extend and retract multiple sections within a GUIGUIFrame ---------- Subdivide GUIs into many adjustable framesGUIListViewEx ------- Insert, delete, move, drag, sort, edit and colour ListView itemsGUITreeViewEx ------ Check/clear parent and child checkboxes in a TreeViewMarquee ----------- Scrolling tickertape GUIsNoFocusLines ------- Remove the dotted focus lines from buttons, sliders, radios and checkboxesNotify ------------- Small notifications on the edge of the displayScrollbars ----------Automatically sized scrollbars with a single commandStringSize ---------- Automatically size controls to fit textToast -------------- Small GUIs which pop out of the notification area Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now